CISO-as-a-Service

An interim security leader providing strategic direction without a full-time hire. Three packages from SEK 22,500/month.

About the service

Not every organisation needs a full-time CISO, but every organisation needs strategic security leadership. Our CISO-as-a-Service gives you access to experienced expertise at the level you need.

A Chief Information Security Officer (CISO) is responsible for driving an organisation's information security programme at a strategic level. The role demands deep expertise across technology, risk, and governance, and finding the right person as a full-time hire is both difficult and costly.

With CISO-as-a-Service you gain access to an experienced security leader who works as part of your organisation, but at the scope that suits your needs. We offer the service in three packages — Base, Standard and Partner — ranging from two days a month to two days a week.

Our CISO service is not a generic consulting role. We immerse ourselves in your business, your challenges, and your objectives, and then build a security programme tailored to your specific organisation. We report directly to your executive team and take ownership of progress.

Quick facts

Deliverables
6 concrete deliverables
Process
4 steps from start to result
Often combined with
NIS2, ISO 27001, Risk Management

Is this right for you?

Do you need a CISO?

The need for a CISO is growing in step with regulatory requirements and the threat landscape. If you lack dedicated security expertise at the leadership level, or if your current resource needs reinforcement, we can help.

Mid-sized companies without a dedicated CISO
Fast-growing technology companies
Public sector and municipalities
Organisations subject to NIS2 requirements
Companies in a growth or restructuring phase

Benefits

Why CISO with Verit

01

Immediate expertise

Instead of a recruitment process spanning 3–6 months, you gain immediate access to an experienced CISO with a proven track record in management systems, regulatory compliance, and security governance.

02

Flexible engagement

We scale the engagement to your needs, from two days a month to two days a week, with the option to go further during intensive periods such as NIS2 implementation or certification projects. You pay for the time you actually need.

03

Strategic and operational

Our CISO operates at every level: from the boardroom and executive presentations to hands-on work with risk assessments, policies, and incident management. You get a complete solution that bridges strategy and practice.

Packages and pricing

CISO-as-a-Service at three levels

Not every organisation needs the same level of security leadership. You choose the scope that matches your needs today and can move between levels as those needs change. A needs assessment at start-up is always included in the first month, whichever package you choose.

Scope 2 days per month

CISO Base

SEK 22,500 per month

For organisations that want strategic direction and an experienced adviser alongside them, without the need for ongoing operational presence.

  • Information security strategy and annual plan
  • Monthly review with the executive team
  • Advisory on policies and governing documents
  • Priority availability in the event of a serious incident

Suits organisations with some in-house IT and security capacity that lack the strategic leadership.

Most popular
Scope 1 day per week

CISO Standard

SEK 42,500 per month

A present security leader who drives the work forward every week and takes ownership of getting things done.

  • Everything in Base
  • Risk assessments and ongoing risk management
  • Management reporting and board presentations
  • Development and maintenance of policies and governing documents
  • Knowledge transfer to internal resources
  • Incident support

Suits mid-sized companies, fast-growing technology companies and organisations subject to NIS2.

Scope 2 days per week

CISO Partner

SEK 79,500 per month

For organisations with high regulatory demands or an extensive security programme that needs real momentum. Your part-time security leader, deeply involved in the business.

  • Everything in Standard
  • Audit preparation and certification support
  • Operational leadership of security projects
  • Participation in the executive team
  • Extended incident support with short response time
  • Scalable capacity during intensive periods

Suits the public sector, regulated businesses and companies in growth or restructuring.

All prices exclude VAT. No commitment beyond an initial three months. Changing package requires one month's notice.

Comparison

Compare the packages

Scope

Base

2 days/month

Standard

1 day/week

Partner

2 days/week

Monthly price

Base

SEK 22,500

Standard

SEK 42,500

Partner

SEK 79,500

Strategy and annual plan

Base

Yes

Standard

Yes

Partner

Yes

Management review

Base

Monthly

Standard

Weekly

Partner

Weekly

Risk assessments

Base

Advisory

Standard

Yes

Partner

Yes

Board reporting

Base

Standard

Yes

Partner

Yes

Policies and governing documents

Base

Advisory

Standard

Yes

Partner

Yes

Knowledge transfer

Base

Standard

Yes

Partner

Yes

Incident support

Base

Priority access

Standard

Yes

Partner

Extended

Audit preparation

Base

Standard

Optional

Partner

Yes

Participation in the executive team

Base

Standard

Optional

Partner

Yes

Working method

Our process

1

Needs assessment

We map your organisation's current state, existing security efforts, and the challenges you face. The result is a clear picture of what type of engagement is needed.

1 week
2

Onboarding

We immerse ourselves in your business, your systems, your risks, and your stakeholders. We establish working methods, reporting lines, and priorities for the first months.

2–3 weeks
3

Ongoing delivery

Regular presence in your organisation. We drive the security programme forward, report to management, handle incidents, and ensure that your objectives are met.

Ongoing
4

Knowledge transfer

We document and transfer knowledge continuously. If you eventually wish to hire a permanent CISO, we support you with recruitment and handover.

Continuous

Securapilot

The tools for effective CISO governance

Our CISO uses Securapilot to give you transparency and control. You always see where you stand and what is happening, without having to wait for the next meeting.

Explore Securapilot
  • Strategic dashboard with security status and KPIs
  • Risk reporting tailored for management and the board
  • Action tracking with clear responsibilities and deadlines
  • Incident management and documentation

Results

What you get

  • Information security strategy tailored to your business
  • Regular management reporting and board presentations
  • Risk assessments and incident support
  • Policies and governing documents
  • Knowledge transfer to internal resources
  • Supervisory and audit preparation

Frequently asked questions

Questions & answers

What does CISO-as-a-Service cost?
We work with three fixed packages: CISO Base at SEK 22,500 per month (2 days per month), CISO Standard at SEK 42,500 per month (1 day per week) and CISO Partner at SEK 79,500 per month (2 days per week). All prices exclude VAT, and a needs assessment at start-up is included in the first month.
How much time does an external CISO spend with us?
That depends on the package you choose: 2 days per month in Base, 1 day per week in Standard and 2 days per week in Partner. During intensive periods such as a NIS2 implementation or a certification project the engagement can be scaled up temporarily.
Can an external CISO report to our board?
Absolutely. We regularly present to executive teams and boards, with reports tailored to the audience. Strategic decision-support material, risk status, and progress reports are a core part of the delivery.
How does this differ from a traditional consultant?
A traditional consultant often delivers a report and moves on. Our CISO service involves an ongoing commitment where we take ownership of progress, drive the work forward, and remain available to your organisation over time.

Discuss CISO-as-a-Service

Tell us about your situation and we will discuss which level fits. Changing package requires one month's notice.

Book a meeting